home.social

#shadowit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #shadowit, aggregated by home.social.

  1. 3/3

    This is a supply chain story dressed as a CVE. The ecosystem was built too fast. Security assumed it would catch up. It hasn't.

    Digital sovereignty without perimeter defence is just security theatre. If you're running MCP servers and you skip the proxy because 'it adds complexity,' you've already lost.

    haunted.lighthouse.co.im/artic

    #BadHost #CVE202648710 #Starlette #FastAPI #MCP #SupplyChain #CyberSecurity #DigitalSovereignty #ShadowIT #Architecture

  2. Did you already listen to our latest episode "Sleep Mode in Production" ?

    A warehouse suddenly stopped operating — not because of a cyberattack, but because a laptop entered sleep mode.

    A known system solved a real business problem, made its way into production, skipped a few operational questions… and eventually became more critical than anyone expected.

    Listen now: ithorrorstories.eu/#ep14

    #technology #IT #ShadowIT #DevOps #Infrastructure #Podcast #ITHorrorStories

  3. Did you already listen to our latest episode "Sleep Mode in Production" ?

    A warehouse suddenly stopped operating — not because of a cyberattack, but because a laptop entered sleep mode.

    A known system solved a real business problem, made its way into production, skipped a few operational questions… and eventually became more critical than anyone expected.

    Listen now: ithorrorstories.eu/#ep14

    #technology #IT #ShadowIT #DevOps #Infrastructure #Podcast #ITHorrorStories

  4. Did you already listen to our latest episode "Sleep Mode in Production" ?

    A warehouse suddenly stopped operating — not because of a cyberattack, but because a laptop entered sleep mode.

    A known system solved a real business problem, made its way into production, skipped a few operational questions… and eventually became more critical than anyone expected.

    Listen now: ithorrorstories.eu/#ep14

    #technology #IT #ShadowIT #DevOps #Infrastructure #Podcast #ITHorrorStories

  5. Did you already listen to our latest episode "Sleep Mode in Production" ?

    A warehouse suddenly stopped operating — not because of a cyberattack, but because a laptop entered sleep mode.

    A known system solved a real business problem, made its way into production, skipped a few operational questions… and eventually became more critical than anyone expected.

    Listen now: ithorrorstories.eu/#ep14

    #technology #IT #ShadowIT #DevOps #Infrastructure #Podcast #ITHorrorStories

  6. Did you already listen to our latest episode "Sleep Mode in Production" ?

    A warehouse suddenly stopped operating — not because of a cyberattack, but because a laptop entered sleep mode.

    A known system solved a real business problem, made its way into production, skipped a few operational questions… and eventually became more critical than anyone expected.

    Listen now: ithorrorstories.eu/#ep14

  7. New episode: Sleep Mode in Production.

    A warehouse outage caused by a laptop entering sleep mode sounds ridiculous… until you realize it really can happen.

    Shadow IT, missing operational checks, and “temporary” solutions reaching production.

    Find all links to listen on our website : ithorrorstories.eu/#ep14

    Spotify : open.spotify.com/show/7LqbtykS
    Apple Music : podcasts.apple.com/us/podcast/
    YouTube : music.youtube.com/playlist?lis
    Deezer : link.deezer.com/s/30dyH3RoKvN8

    #technology #ShadowIT #DevOps #ITOperations #ITHorrorStories

  8. New episode: Sleep Mode in Production.

    A warehouse outage caused by a laptop entering sleep mode sounds ridiculous… until you realize it really can happen.

    Shadow IT, missing operational checks, and “temporary” solutions reaching production.

    Find all links to listen on our website : ithorrorstories.eu/#ep14

    Spotify : open.spotify.com/show/7LqbtykS
    Apple Music : podcasts.apple.com/us/podcast/
    YouTube : music.youtube.com/playlist?lis
    Deezer : link.deezer.com/s/30dyH3RoKvN8

    #technology #ShadowIT #DevOps #ITOperations #ITHorrorStories

  9. New episode: Sleep Mode in Production.

    A warehouse outage caused by a laptop entering sleep mode sounds ridiculous… until you realize it really can happen.

    Shadow IT, missing operational checks, and “temporary” solutions reaching production.

    Find all links to listen on our website : ithorrorstories.eu/#ep14

    Spotify : open.spotify.com/show/7LqbtykS
    Apple Music : podcasts.apple.com/us/podcast/
    YouTube : music.youtube.com/playlist?lis
    Deezer : link.deezer.com/s/30dyH3RoKvN8

    #technology #ShadowIT #DevOps #ITOperations #ITHorrorStories

  10. New episode: Sleep Mode in Production.

    A warehouse outage caused by a laptop entering sleep mode sounds ridiculous… until you realize it really can happen.

    Shadow IT, missing operational checks, and “temporary” solutions reaching production.

    Find all links to listen on our website : ithorrorstories.eu/#ep14

    Spotify : open.spotify.com/show/7LqbtykS
    Apple Music : podcasts.apple.com/us/podcast/
    YouTube : music.youtube.com/playlist?lis
    Deezer : link.deezer.com/s/30dyH3RoKvN8

    #technology #ShadowIT #DevOps #ITOperations #ITHorrorStories

  11. New episode: Sleep Mode in Production.

    A warehouse outage caused by a laptop entering sleep mode sounds ridiculous… until you realize it really can happen.

    Shadow IT, missing operational checks, and “temporary” solutions reaching production.

    Find all links to listen on our website : ithorrorstories.eu/#ep14

    Spotify : open.spotify.com/show/7LqbtykS
    Apple Music : podcasts.apple.com/us/podcast/
    YouTube : music.youtube.com/playlist?lis
    Deezer : link.deezer.com/s/30dyH3RoKvN8

  12. A recent Pentagon vendor cutoff exposed how many enterprises silently rely on hidden AI tools—think Claude, SDKs, and automated agents tucked away in Shadow IT. The fallout raises urgent questions about security, compliance, and true AI independence. Dive into the details to see what your organization might be missing. #AIDependencies #PentagonVendor #ShadowIT #EnterpriseSecurity

    🔗 aidailypost.com/news/pentagon-

  13. Is your "strategy" just a collection of manual spreadsheets? We call this Shadow Data Collapse. When the one person who understands the macros leaves, your "insights" go with them. Stop managing liabilities and start fixing the process.

    ​Measure your friction before the collapse:
    shaolindataservices.com/#diagn

    ​#DataStrategy #ShadowIT #Ops #ShaolinData #Analytics

  14. Is your "strategy" just a collection of manual spreadsheets? We call this Shadow Data Collapse. When the one person who understands the macros leaves, your "insights" go with them. Stop managing liabilities and start fixing the process.

    ​Measure your friction before the collapse:
    shaolindataservices.com/#diagn

    ​#DataStrategy #ShadowIT #Ops #ShaolinData #Analytics

  15. OpenClaw just hit 160 000 ⭐ on GitHub, showing how shadow‑IT tools are becoming mainstream. Its AI‑driven local agent lets users bypass corporate controls, raising fresh enterprise‑security questions. How should orgs respond to unauthorized software and shifting user permissions? Dive into the analysis. #OpenClaw #ShadowIT #AIAGENT #EnterpriseSecurity

    🔗 aidailypost.com/news/openclaw-

  16. Adventures in Uptime: The Desk Production Server #13

    You haven't known fear until you've been asked to "just reboot a PC" and discovered it's actually a production server that has lived under a desk for years.

    "Enterprise-grade infrastructure" sometimes just means a desktop tower with a "Do Not Unplug" sticky note. 😅

    The full story is available on my blog: alexnuttinck.dev/posts/adventu

    #AdventuresInUptime #DevOps #Sysadmin #ShadowIT #TechHumor

  17. Ever wondered what Shadow IT actually is? Think of it as business folks building their own secret solutions without telling IT. If you’re clueless, stay blessed—ignorance really is bliss in this case.

    Find out more in our latest episode Shadow IT Reports, available now on all podcast networks and where-ever you get your panic attacks.

    Spotify : open.spotify.com/show/7LqbtykS
    Apple Music : podcasts.apple.com/us/podcast/
    YouTube : music.youtube.com/playlist?lis
    Deezer : link.deezer.com/s/30dyH3RoKvN8

    #podcast #tech #shadowit #techlife #ithumor #cybersecurity

  18. 📚 Frameworks
    ===================

    Executive summary: Ownerless or forgotten IT assets — orphaned physical/virtual servers, stale test environments, and inactive service accounts — represent persistent security, compliance, and cost risks. The core recommendation is to operationalize discovery, reconciliation, and lifecycle controls rather than relying on ad-hoc manual inventories.

    Technical details:
    • Orphaned servers: common after migrations, M&A, or expired projects; LetsEncrypt telemetry noted that in 2024 roughly half of renewal requests came from devices no longer associated with the domain (≈1,000,000 devices globally).
    • Forgotten accounts: technical service accounts, contractor and non-personalized accounts that remain privileged despite inactivity.
    • Detection components: an Automated Discovery and Reconciliation (AD&R) workflow that merges network scanning results and cloud inventory with the Configuration Management Database (CMDB), plus external vulnerability scans covering all public IP addresses.

    Analysis:
    • Attack surface: exposed, unpatched services and privileged inactive accounts are common initial access vectors and persistence mechanisms.
    • Operational gap: CMDBs are often stale or incomplete; cloud and network inventories live in silos, producing conflicting records that hide orphaned assets.

    Detection guidance:
    • Consolidate inventories: correlate network scan outputs, cloud provider inventories, and CMDB records to flag mismatches and unassociated hosts.
    • Directory hygiene: schedule regular Active Directory (or equivalent) analyses to list accounts with no activity over defined windows and enumerate assigned permissions.
    • External scanning: scan all public IPs to identify exposed services and historical vulnerabilities that may have been patched on production but left open on forgotten assets.

    Mitigation and response:
    • Decommissioning process: formalize documented steps that require verified data migration and certified data destruction prior to powering down, recycling, or repurposing hardware.
    • Quarantine posture: until decommissioning is complete, move suspect servers into an isolated subnet to reduce exposure.
    • Test environment controls: implement automated lifecycle policies to create and dismantle test environments based on project timelines or inactivity; enforce strict isolation and forbid use of real, non-anonymized production data.
    • Identity controls: integrate an Identity and Access Management (IAM) solution to scale account lifecycle management, enforce least privilege, and automate removal of excessive permissions.

    Limitations and considerations:
    • Inventory quality: AD&R effectiveness depends on the completeness of source inventories and on reliable CMDB data.
    • Change management: organizational buy-in is needed for automated decommissioning and account removal policies.

    🔹 cmdb #iam #shadowIT #asset_management #letsEncrypt

    🔗 Source: kaspersky.com/blog/forsaken-se

  19. docker.com/blog/ai-insider-thr - We all want #AI to make our lives easier and more productive. But is AI the new insider #security threat? #ShadowIT was bad. What about #ShadowAI?

  20. Google Opal is cool. Like dangerously cool.
    No code AI mini apps mean employees can build powerful tools in minutes. That is innovation and also shadow AI, unclear data boundaries, and a lot of who approved this energy.
    We break down what this means for privacy, governance, and B2B teams trying to keep up.
    👉 medium.com/@biytelum/googles-o
    #GoogleOpal #DataPrivacy #AI #B2B #ShadowIT

  21. Google Opal is cool. Like dangerously cool.
    No code AI mini apps mean employees can build powerful tools in minutes. That is innovation and also shadow AI, unclear data boundaries, and a lot of who approved this energy.
    We break down what this means for privacy, governance, and B2B teams trying to keep up.
    👉 medium.com/@biytelum/googles-o
    #GoogleOpal #DataPrivacy #AI #B2B #ShadowIT

  22. Google Opal lowers the barrier to building AI tools — fast.
    As an experimental Google Labs product, it has no enterprise SLAs and limited security controls, and Google notes that a small subset of prompts may be reviewed.
    For organizations, the risk isn’t innovation — it’s employee-built AI handling business or personal data without clear governance.
    #GoogleOpal #GoogleLabs #DataPrivacy #Compliance #B2B #AI #ShadowIT

  23. Google Opal lowers the barrier to building AI tools — fast.
    As an experimental Google Labs product, it has no enterprise SLAs and limited security controls, and Google notes that a small subset of prompts may be reviewed.
    For organizations, the risk isn’t innovation — it’s employee-built AI handling business or personal data without clear governance.
    #GoogleOpal #GoogleLabs #DataPrivacy #Compliance #B2B #AI #ShadowIT

  24. 90% of employees use unsanctioned AI. Not only does that risk cybersecurity, but it also puts most companies' IP at risk.

    fortune.com/2025/08/19/shadow-

  25. On paper, I am in no way qualified to replace my wife's employer's IT department.

    But based on what I've personally experienced, neither are they.

    #ShadowIT

  26. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHatUSA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're honored to share this eye-opening Brand Story conversation thanks to our friends at runZero 🙏

    The Often-Overlooked Truth in #Cybersecurity: Seeing the Unseen in Vulnerability Management

    Most successful breaches don't happen because defenders ignored known vulnerabilities. They happen because attackers exploited assets that organizations never knew existed.

    HD‏​​​​​​​​​​‏ ⁢​​​​Moore, founder and CEO of runZero and creator of #Metasploit, reveals the uncomfortable truth: organizations routinely miss half their actual attack surface. Through decades of penetration testing high-security environments, Moore discovered that traditional discovery methods only find properly managed systems while #shadowIT, legacy hardware, and misconfigured devices remain invisible.

    Key insights from our conversation:

    • When using attacker-grade discovery techniques, asset counts typically DOUBLE what organizations thought they had

    • The industry's CVE obsession creates false security while real attacks exploit misconfigurations and zero-days

    • Unknown assets—from IoT devices to forgotten servers—bypass even sophisticated security controls

    • Traditional agent-based tools can't see what attackers see

    #RunZero inverts the traditional model by starting with unauthenticated discovery that mirrors how attackers actually probe networks. This reveals the true attack surface and transforms vulnerability management from reactive patching to strategic risk reduction.

    📺 Watch the video: youtu.be/hkKJsKUugIU

    🎧 Listen to the podcast: brand-stories-podcast.simpleca 📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about RunZero: itspm.ag/runzero-5733

    ✦ Catch more stories from RunZero: itspmagazine.com/directory/run

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #VulnerabilityManagement #AssetDiscovery #AttackSurface #BlackHatUSA #BHUSA25 #ShadowIT #SecurityVisibility #Metasploit #ZeroDay #tech #technology #cybersecurity

  27. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHatUSA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're honored to share this eye-opening Brand Story conversation thanks to our friends at runZero 🙏

    The Often-Overlooked Truth in #Cybersecurity: Seeing the Unseen in Vulnerability Management

    Most successful breaches don't happen because defenders ignored known vulnerabilities. They happen because attackers exploited assets that organizations never knew existed.

    HD‏​​​​​​​​​​‏ ⁢​​​​Moore, founder and CEO of runZero and creator of #Metasploit, reveals the uncomfortable truth: organizations routinely miss half their actual attack surface. Through decades of penetration testing high-security environments, Moore discovered that traditional discovery methods only find properly managed systems while #shadowIT, legacy hardware, and misconfigured devices remain invisible.

    Key insights from our conversation:

    • When using attacker-grade discovery techniques, asset counts typically DOUBLE what organizations thought they had

    • The industry's CVE obsession creates false security while real attacks exploit misconfigurations and zero-days

    • Unknown assets—from IoT devices to forgotten servers—bypass even sophisticated security controls

    • Traditional agent-based tools can't see what attackers see

    #RunZero inverts the traditional model by starting with unauthenticated discovery that mirrors how attackers actually probe networks. This reveals the true attack surface and transforms vulnerability management from reactive patching to strategic risk reduction.

    📺 Watch the video: youtu.be/hkKJsKUugIU

    🎧 Listen to the podcast: brand-stories-podcast.simpleca 📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about RunZero: itspm.ag/runzero-5733

    ✦ Catch more stories from RunZero: itspmagazine.com/directory/run

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #VulnerabilityManagement #AssetDiscovery #AttackSurface #BlackHatUSA #BHUSA25 #ShadowIT #SecurityVisibility #Metasploit #ZeroDay #tech #technology #cybersecurity

  28. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHatUSA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're honored to share this eye-opening Brand Story conversation thanks to our friends at runZero 🙏

    The Often-Overlooked Truth in #Cybersecurity: Seeing the Unseen in Vulnerability Management

    Most successful breaches don't happen because defenders ignored known vulnerabilities. They happen because attackers exploited assets that organizations never knew existed.

    HD‏​​​​​​​​​​‏ ⁢​​​​Moore, founder and CEO of runZero and creator of #Metasploit, reveals the uncomfortable truth: organizations routinely miss half their actual attack surface. Through decades of penetration testing high-security environments, Moore discovered that traditional discovery methods only find properly managed systems while #shadowIT, legacy hardware, and misconfigured devices remain invisible.

    Key insights from our conversation:

    • When using attacker-grade discovery techniques, asset counts typically DOUBLE what organizations thought they had

    • The industry's CVE obsession creates false security while real attacks exploit misconfigurations and zero-days

    • Unknown assets—from IoT devices to forgotten servers—bypass even sophisticated security controls

    • Traditional agent-based tools can't see what attackers see

    #RunZero inverts the traditional model by starting with unauthenticated discovery that mirrors how attackers actually probe networks. This reveals the true attack surface and transforms vulnerability management from reactive patching to strategic risk reduction.

    📺 Watch the video: youtu.be/hkKJsKUugIU

    🎧 Listen to the podcast: brand-stories-podcast.simpleca 📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about RunZero: itspm.ag/runzero-5733

    ✦ Catch more stories from RunZero: itspmagazine.com/directory/run

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #VulnerabilityManagement #AssetDiscovery #AttackSurface #BlackHatUSA #BHUSA25 #ShadowIT #SecurityVisibility #Metasploit #ZeroDay #tech #technology #cybersecurity

  29. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHatUSA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're honored to share this eye-opening Brand Story conversation thanks to our friends at runZero 🙏

    The Often-Overlooked Truth in #Cybersecurity: Seeing the Unseen in Vulnerability Management

    Most successful breaches don't happen because defenders ignored known vulnerabilities. They happen because attackers exploited assets that organizations never knew existed.

    HD‏​​​​​​​​​​‏ ⁢​​​​Moore, founder and CEO of runZero and creator of #Metasploit, reveals the uncomfortable truth: organizations routinely miss half their actual attack surface. Through decades of penetration testing high-security environments, Moore discovered that traditional discovery methods only find properly managed systems while #shadowIT, legacy hardware, and misconfigured devices remain invisible.

    Key insights from our conversation:

    • When using attacker-grade discovery techniques, asset counts typically DOUBLE what organizations thought they had

    • The industry's CVE obsession creates false security while real attacks exploit misconfigurations and zero-days

    • Unknown assets—from IoT devices to forgotten servers—bypass even sophisticated security controls

    • Traditional agent-based tools can't see what attackers see

    #RunZero inverts the traditional model by starting with unauthenticated discovery that mirrors how attackers actually probe networks. This reveals the true attack surface and transforms vulnerability management from reactive patching to strategic risk reduction.

    📺 Watch the video: youtu.be/hkKJsKUugIU

    🎧 Listen to the podcast: brand-stories-podcast.simpleca 📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about RunZero: itspm.ag/runzero-5733

    ✦ Catch more stories from RunZero: itspmagazine.com/directory/run

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #VulnerabilityManagement #AssetDiscovery #AttackSurface #BlackHatUSA #BHUSA25 #ShadowIT #SecurityVisibility #Metasploit #ZeroDay #tech #technology #cybersecurity

  30. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHatUSA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're honored to share this eye-opening Brand Story conversation thanks to our friends at runZero 🙏

    The Often-Overlooked Truth in #Cybersecurity: Seeing the Unseen in Vulnerability Management

    Most successful breaches don't happen because defenders ignored known vulnerabilities. They happen because attackers exploited assets that organizations never knew existed.

    HD‏​​​​​​​​​​‏ ⁢​​​​Moore, founder and CEO of runZero and creator of #Metasploit, reveals the uncomfortable truth: organizations routinely miss half their actual attack surface. Through decades of penetration testing high-security environments, Moore discovered that traditional discovery methods only find properly managed systems while #shadowIT, legacy hardware, and misconfigured devices remain invisible.

    Key insights from our conversation:

    • When using attacker-grade discovery techniques, asset counts typically DOUBLE what organizations thought they had

    • The industry's CVE obsession creates false security while real attacks exploit misconfigurations and zero-days

    • Unknown assets—from IoT devices to forgotten servers—bypass even sophisticated security controls

    • Traditional agent-based tools can't see what attackers see

    #RunZero inverts the traditional model by starting with unauthenticated discovery that mirrors how attackers actually probe networks. This reveals the true attack surface and transforms vulnerability management from reactive patching to strategic risk reduction.

    📺 Watch the video: youtu.be/hkKJsKUugIU

    🎧 Listen to the podcast: brand-stories-podcast.simpleca 📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about RunZero: itspm.ag/runzero-5733

    ✦ Catch more stories from RunZero: itspmagazine.com/directory/run

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #VulnerabilityManagement #AssetDiscovery #AttackSurface #BlackHatUSA #BHUSA25 #ShadowIT #SecurityVisibility #Metasploit #ZeroDay #tech #technology #cybersecurity

  31. Good luck to anyone tackling shadow AI. Most companies haven't yet managed to get shadow IT under control, and we are now presenting them with an even bigger problem.

    thehackernews.com/expert-insig